Bryan Brake, Amanda Berlin, and Brian Boettcher

BrakeSec Education Podcast

News EN ↓ 463 episodes

A podcast about the world of Cybersecurity, Privacy, Compliance, and Regulatory issues that arise in today's workplace. Co-hosts Bryan Brake, Brian Boettcher, and Amanda Berlin teach concepts that aspiring Information Security professionals need to know, or refresh the memories of seasoned veterans.

Author

Bryan Brake, Amanda Berlin, and Brian Boettcher

Category

News

Podcast website

www.youtube.com

Latest episode

Jul 17, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Ratproxy and on being a better Infosec Professional 18.08.2014

This week, we go into a proxy program called "Ratproxy", discussed it's ins and outs.  Plus, Mr. Boettcher and I have a discussion about how we as infosec people should work with developers and IT professionals to provide them training and understanding of security concepts. https://code.google.com/p/ratproxy/ http://blog.secureideas.com/2012/07/how-to-setup-ratproxy-on-windows.html         Ratpro...

Introduction to Nmap, Part 2 Video 10.08.2014

Here is Part 2 of our video for understanding the basics of Nmap.  I discuss some of the logging output, the scripts found in Nmap, and the output that Nmap gives you for reporting or comparison later.   I really did want to go more into the Lua portion of the scripting engine, and perhaps make a simple script, but time constraints halted that. I hope to get more adept at video creation and hopefu...

Risk Management discussion with Josh Sokol - Part 2 10.08.2014

This week we take some time to talk about risk management with Josh Sokol.  This is part 2 from our interview with him last week... We talk some more about Simple Risk from the POV of Risk Management, as well as the licensing/modification of Simple Risk. Mr. Boettcher and Josh discuss the merits of Qualitative vs. Quantitative Risk Analysis, and which one is better... We also discuss NIST 800 seri...

Interview with creator of Simple Risk, Josh Sokol! (Part 1) 04.08.2014

Josh Sokol is on the International OWASP board of directors in addition to being the Information Security Program Owner at National Instruments in Austin, Texas. This week, he sat down with Brakeing Down Security to talk about Simple Risk, his homebrew application that assists people and organizations in managing their business risk, and at a much nicer cost that other GRC applications (it's free!...

Flashback: Sqlmap - a little how-to, and getting your developers involved in using it. 28.07.2014

This is a flashback from July 2015.  Mr. Boettcher and I discussed SQLMAP, a tool that can automate the process of pentesting databases and even registries on Windows.  We discuss some functions of the program and why developers should get training on these. Mr. Boettcher and I talk about how Infosec professionals should help to educate QA and Developers to be able to look at their processes and i...

Part 2 with Georgia Weidman! 21.07.2014

It only gets better in Part 2 of our Interview with Georgia Weidman, Author, Security Researcher and Creator of the Smartphone Pentesting Framework.   She talks about how people underestimate the mobile platform for pentesting purposes, and we even find out that in addition to Teaching a class on exploit development at BlackHat this year, she's going to be helping a great organization overseas. We...

Nmap (pt1) Video 14.07.2014

So, I uploaded this little tutorial of nmap, a very nice tool I use on a regular basis, both at home and at work. I did some basic scans, showed off the command line and the Windows 'Zenmap' version, as well as discussed some regularly used switches. The next video I do about nmap will discuss more switches, the Nmap Scripting Engine (NSE), and how to format reports and the output nmap provides.  ...

Part 1 with Author and Mobile Security Researcher Georgia Weidman! 14.07.2014

We have a real treat the next two weeks.  Author and Mobile Security Researcher Georgia Weidman, who we also found out will be providing exploit development training at Black Hat this year. She is the author of an awesome book "Penetration Testing: A Hands-On Introduction to Hacking" ( http://www.amazon.com/Penetration-Testing-Hands-On-Introduction-Hacking/dp/1593275641/ref=sr_1_1?ie=UTF8&qid=1405...

Establishing your Information Security Program - Part 2 07.07.2014

This is the continuation of our podcast from last week with Phil Beyer. We started out talking about risk registers, and we end the podcast with a little Q&A about positions in companies (Chief Risk Officer, Chief Data Protection Officer), and whether these positions are useful.    Risk registers - http://en.wikipedia.org/wiki/Risk_register   Intro "Private Eye", transition "Mining by Moonlight",...

Establishing your Information Security Program - Part 1 30.06.2014

Establishing an Information Security program can make or break an organization. So what do you need to get that started?  We have friend of the show Phil Beyer come in and discuss with us the five steps of the creation of an Information Security Program.  Join us for Part 1, and next week, we'll finish up with a little Q&A, as well as what a 'risk register' is.             Intro "Private Eye", and...

OWASP Top Ten: 1-5 23.06.2014

We finished up the OWASP Top Ten List. We discussed Injection, XSS, and other goodness.  Find out what makes the Top 5 so special.       http://risky.biz/fss_idiots   - Risky Business Interview concerning Direct Object Reference and First State Superannuation http://oauth.net/2/ - Great information on OAUTH 2.0.       Intro "Private Eye", and Outro "Honeybee" created by Kevin MacLeod (incompetech....

OWASP Top Ten: Numbers 6 - 10 16.06.2014

As we wade through the morass of the Infosec swamp, we come across the OWASP 2013 report of web app vulnerabilities. Since Mr. Boettcher and I find ourselves often attempting to explain these kinds of issues to people on the Internet and in our daily lives, we thought it would be prudent to help shed some light on these. So this week, we discuss the lower of the top 10, the ones that aren't as gla...

Talk with Guillaume Ross - Part 2 (all things cloud) 09.06.2014

This is part 2 of our podcast interview with Guillaume Ross, Infosec professional who is well versed with the intricacies of various cloud architectures, whether they are IaaS, PaaS, or SaaS.  This part of the podcast discussed how contracts are established, and we ask if smaller cloud providers have a chance against behemoths like Google, Amazon, and Microsoft.   Links brought up during the inter...

It all goes in "the cloud" (Part 1) 01.06.2014

Brian and I interviewed Mr. Guillaume Ross (@gepeto42), an Information Security professional who helps organizations get themselves situated into cloud based solutions. We get a better understanding of why people would want to put their info into the 'cloud' and how they are different than traditional co-lo and datacenters.   Guillaume's Blog: http://blog.binaryfactory.ca/   AWS (amazon) Security...

Video 2: BONUS!!!! Kismet Video! Video 27.05.2014

As promised, I am posting a video I made explaining how to setup Kismet to do wireless scans. The only pre-requisites you need are Vmware (it will work the same in VirtualBox), and a VM of Kali linux. The only real difference is the message that asks where the wireless adapter should connect to. It's my first attempt editing a video, so please be kind

Wireless scans with Kismet and Aircrack-ng 26.05.2014

Mr. Boettcher and I had a great time this week.  We talked all about doing wireless audits for PCI using Kismet and Aircrack-ng, and talked about some capabilities of both.   Alfa AWUS051NH (works in Kali/Backtrack) (no sponsor link): http://www.amazon.com/gp/offer-listing/B002BFO490/ref=dp_olp_0?ie=UTF8&condition=all kismetwireless.net  Using Karma with a pineapple to fool clients into connecting...

PGP and GPG -- protect your data 18.05.2014

Sharing information between people and organizations can be a sensitive issue, especially if the information being shared is of mutual importance.  This week, we break down PGP and it's open source cousin GPG.  We discuss how last week's podcast about hashing, encoding, and encryption are all bundled up neatly with PGP, and give you some examples of software you can use on Mac, Windows, and Linux....

clearing up some terminology (hashing, encryption, encoding) 13.05.2014

Ever heard someone mention AES Encoding, or MD5 Encryption?   Many people in IT, Infosec, and Software development get confused about what Hashing, Encrypting, and Encoding.  We hack through the definition forest, looking for that Sequoia of understanding. We also talk about Symantec's remarks that 'Antivirus is dead' and 'not a moneymaker', and what that means to the industy as a whole.   "Enkryp...

Browsing more Securely 05.05.2014

This week, we find ways to increase security when browsing the EWW (Evil Wide Web). We give a shout-out to WhiteHatSec's Aviator browser as a way for everyone to have an eleveated security posture with very little configuration required. And Mr. Boettcher and I talk about some of the plugins we use to make ourselves more secure. And Mr. Boettcher surprises me with his proclivities toward farmyard...

Mandiant 2014 threat report 28.04.2014

Mandiant put out their 2014 Threat Report, and we got into all the meaty goodness.  From the Syrian Electronic Army, Iran, and China's APT1 and APT12. Find out if the bad guys are getting smarter, or if we are just making it easier for them? Have a listen and find out.     Mandiant 2014 report (registration required):  http://connect.mandiant.com/m-trends_2014       Intro "Private Eye", transition...

Episode 13 - 2014 Verizon PCI Report 21.04.2014

Since 2006, Verizon has put out their yearly PCI report.  We break it down, and discuss the merits of the report.   2014 Verizon Report: www.verizonenterprise.com/resources/reports/rp_pci-report-2014_en_xg.pdf           Intro "Private Eye", transition "Mining by Moonlight", and Outro "Honeybee" created by Kevin MacLeod (incompetech.com)  Licensed under Creative Commons: By Attribution 3.0 http://c...

Episode 12, Part 2 of our interview with Phil Beyer! 15.04.2014

This is Part 2 of our interview with Phil Beyer.  We asked him about the difference between mentoring and coaching, and we end the podcast talking about influence, the types of influence and ways to gain influence.             Intro "Private Eye", transition "Mining by Moonlight", and Outro "Honeybee" created by Kevin MacLeod (incompetech.com)  Licensed under Creative Commons: By Attribution 3.0 h...

Special Report: Heartbleednado-apoco-geddon 14.04.2014

Whois for heartbleed was registered 5 April 2014 by Marko Laasko:   Whois Server Version 2.0 Domain names in the .com and .net domains can now be registered with many different competing registrars. Go to http://www.internic.net for detailed information. Domain Name: HEARTBLEED.COM Registry Domain ID: 1853534635_DOMAIN_COM-VRSN Registrar WHOIS Server: whois.godaddy.com Registrar URL: http://www.go...

Episode 11, Part 1: Interview with Phil Beyer 07.04.2014

This week, we're leaving the Infosec track a bit, but this interview may be more important to being a person's development as a good Infosec person. We interviewed Mr. Phil Beyer, Director of Information Security for the Advisory Board Company.  In addition to being a past president of the Capitol of Texas ISSA Chapter, he co-founded the Texas CISO Council, a regional steering committee composed o...

Video1: quick renaming shortcut with Sed Video 04.04.2014

I take a few minutes to explain a quick mass renaming shortcut using sed I use when I have multiple files that I need to rename.  I used the example of spaces in filenames, but you can use this to append a name to multiple files. Another way to easily change files is to use the 'tr' command. You can change a filename from all lowercase to all uppercase letters, or even remove non-printable charact...

Listen to the BrakeSec Education Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.